Skip to content

Third-Party Risk Management

What is Third-Party Risk Management?

The process of identifying, assessing, and managing risks associated with outsourcing to or partnering with external organisations. Includes vendor due diligence and ongoing monitoring.

Risk Management

What the standards actually require on third-party risk management

Requirements naming third-party risk management across 6 standards, quoted from the control text.

Third party service providers are subject to due diligence, contractual security requirements, and ongoing monitoring.

IS-IX.A.1 · Third Party Risk Management
OSFI B-131 control

Operate third-party risk management per OSFI B-13 Domain 4 + complementary OSFI Guideline B-10 Outsourcing of Business Activities and Functions.

OSFIB13-4 · Third-Party Risk Management and Cloud

Information security requirements for suppliers and service providers. Assessment of third-party security posture. Contractual security requirements. Supply chain risk management for automotive data.

TISAX-IS-03 · Third-Party Risk Management
PCI P2PE5 controls

Due diligence and onboarding. Control from PCI P2PE framework, domain: PCI P2PE: Third-Party Risk Management.

PCI-P2PE-16 · Due diligence and onboarding

Due diligence and onboarding. Control from PCI PIN Security framework, domain: PCI PIN Security: Third-Party Risk Management.

PCI-PIN-16 · Due diligence and onboarding
PCI SSF5 controls

Due diligence and onboarding. Control from PCI SSF framework, domain: PCI SSF: Third-Party Risk Management.

PCI-SSF-16 · Due diligence and onboarding

Questions people ask about third-party risk management

What is Third-Party Risk Management?
The process of identifying, assessing, and managing risks associated with outsourcing to or partnering with external organisations. Includes vendor due diligence and ongoing monitoring.
Why is Third-Party Risk Management important for compliance?
Third-Party Risk Management is a key concept in Risk Management. Understanding third-party risk management helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
What concepts are related to Third-Party Risk Management?
Key concepts related to Third-Party Risk Management include Due Diligence. Understanding these interconnected concepts provides a more comprehensive view of Risk Management requirements and helps organizations build holistic compliance programs.
Which compliance frameworks address Third-Party Risk Management?
Third-Party Risk Management appears in the requirement text of FFIEC IT Examination Handbook, OSFI B-13, TISAX - Trusted Information Security Assessment Exchange, PCI P2PE, PCI PIN Security. Across these standards we have identified 23 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Third-Party Risk Management?
Explore our compliance framework pages to see how third-party risk management applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Third-Party Risk Management applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.